Forum Discussion
ASM detected possible Detection Evasion and HTTP Command injection in traffic
detected possible Detection Evasion and HTTP Command injection in traffic sourcing from hosts destined for F5 VIPs via port http 80. no indication of activity being blocked/denied.
Is this a Application Security, hotfix issue or http security profile configuration?
- Chris_Grant
Employee
Those are part of your ASM security policy. Whether or not it was blocked would be based on your settings. You can read more about attack signatures and evasion settings here:
or here:
https://support.f5.com/kb/en-us/products/big-ip_asm/manuals/product/f5-asm-operations-guide.pdf
Basically ASM is reporting that someone tried to attack your web infrastructure and tried to do it in such a way that they would slip past a web application firewall. Normally this is done by encoding a string multiple times.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com